Adobe Commerce Bug Targeted Immediately After Disclosure
PatchAdobe CommerceMagento Open SourceOur summary
Adobe has released a security update to address CVE-2026-71362, a critical authorization flaw affecting Adobe Commerce and Magento Open Source that was rapidly targeted following its public disclosure. With a CVSS score of 9.1, this vulnerability allows unauthenticated remote attackers to hijack customer sessions and access private data by switching account identities. Although Adobe reported no prior in-the-wild exploitation before the advisory, security firm Sansec confirmed they intercepted initial exploitation attempts shortly after the bug was made public. The fix modifies how customer identity is handled in sessions and applies to all versions up to and including the July 2026 patches.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.